Severity
3.5
Low severity
Details
- CVSS score
- 3.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- CWE ID
Overview
About vulnerability
The packagenode-cli before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
Details
- Affected product:
- cli
- Affected packages:
- cli @ 0.6.6 (+1 more)
node-cli before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.